CybersecurityJobs.io
← Back to all jobs

Job Description

Security Engineer III role for Deloitte’s Cyber Defense & Resilience team, operating as an authorized red team operator to evaluate and strengthen detection, response, and resilience.

Responsibilities

  • Plan and execute red team operations across enterprise environments, web applications, cloud platforms, and endpoints.
  • Emulate advanced threat actors using realistic attack paths, tools, and techniques.
  • Run simulations covering reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration.
  • Evaluate the effectiveness of security controls, monitoring, and incident response processes.
  • Conduct phishing, social engineering, and credential attack exercises where authorized.
  • Develop custom payloads, scripts, and attack workflows to support engagements.
  • Document findings, attack chains, defense gaps, and remediation recommendations.
  • Produce after-action reports and deliver debriefs to technical and leadership stakeholders.
  • Partner with blue teams, detection engineers, and security leadership to improve defensive capabilities.
  • Follow rules of engagement, legal requirements, and operational safety requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical field.
  • Active Top-Secret Clearance.
  • Ability to work onsite up to 5 days per week.
  • Knowledge of network architecture, protocols, and techniques such as tunneling.
  • Hands-on offensive security experience in red teaming, purple teaming, or adversary simulation.
  • Strong understanding of enterprise attack techniques across Windows, Active Directory, Linux, cloud, and identity environments.
  • Experience with command and control frameworks plus techniques for privilege escalation, lateral movement, and evasion.
  • Proficiency with tools including Cobalt Strike, Mythic, Metasploit, BloodHound, Burp Suite, Nmap, and PowerShell or Python.
  • Experience with MITRE ATT&CK mapping and threat emulation.
  • Ability to write high-quality reports connecting technical findings to business risk.
  • Certified Red Team Operator (CRTO) or Offensive Security Certified Professional (OSCP).
  • Ability to travel 20% on average, based on work and client needs.
  • Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Technologies

  • Cobalt Strike
  • Mythic
  • Metasploit
  • BloodHound
  • Burp Suite
  • Nmap
  • PowerShell
  • Python
  • MITRE ATT&CK
  • Active Directory
  • Windows
  • Linux
  • AWS
  • Azure
  • GCP
  • Havoc
  • Sliver
  • SIEM
  • EDR

Preferred

  • Experience with C2 frameworks such as Cobalt Strike, Havoc, Mythic, and Sliver.
  • Experience with cloud red teaming in AWS, Azure, or GCP.
  • Familiarity with detection engineering, SIEM, EDR, and purple team exercises.
  • Experience developing custom tooling or modifying public offensive tools.
  • Knowledge of malware analysis, reverse engineering, or exploit development.

Skills and work style

  • Ability to work independently and collaborate within a team.
  • Strong written and verbal communication skills.
  • Meticulous attention to detail and quality of work product.
  • Ability to build and sustain professional relationships.
  • Ability to lead projects or workstreams.
  • Ability to manage and prioritize multiple tasks in a fast-paced environment.
  • Strong interpersonal skills and professional demeanor.
  • Ability to meet deadlines.
  • Ability to provide clear guidance to others.

Team context

  • Deloitte Cyber supports clients with the unique challenges and opportunities businesses face in cybersecurity.
  • Cyber Defense & Resilience helps clients defend against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence.
  • Supports management and protection of dynamic attack surfaces and delivers rapid crisis and cyber incident response to enable readiness, response, and recovery from business disruptions.

Compensation and incentives

  • Salary range: USD 110,700 - 218,300 per year.
  • You may be eligible for a discretionary annual incentive program subject to program rules.
  • An award, if any, depends on factors including individual and organizational performance.

Similar Jobs